CVE-2019-9808
critical
CVSS v3
—
CVSS v2
—
VIR risk
9.5
Description
If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown origin" as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 66.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2019-9808
Vendor advisory: arch — https://security.archlinux.org/ASA-201903-11
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | fixed | 66.0-1 | |
| debian | sid | fixed | 66.0-1 |
References
Verify integrity in audit chain (admin only). AS-IS.